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CLAIM AMENDMENTS 

1-52 (Cancelled) . 

53. (New) A method of managing network traffic being routed through a 
network connection device, the network traffic being composed of at least 
first and second traffic flows, each traffic flow being composed of at least 
one data packet, and the method comprising: 

(a) receiving at least a first criterion at the network connection 
device for identifying the traffic flow to which a data packet belongs, 

(b) receiving at least a second criterion at the network connection 
device for classifying a traffic flow as belonging to one of at least first 
and second traffic flow classes, 

(c) receiving first and second instructions at the network connection 
device for processing a data packet, the first and second instructions being 
associated with the first and second flow classes respectively, 

(d) storing the first and uecond criteria and the first and second 
instructions on the network connection device, 

(e) receiving a fixst data packet that belongs to the first traffic flow 
at the network connection device, 

(f ) using the first criterion to determine that the first data packet 
belongs to the first traffic flow, 

<g) using the second criterion to determine the traffic flow class to 
which the first traffic flow belongs, and 

(h) processing the first data packet according to tlie instructions 
associated with the flow class to which the first traffic flow belongs. 

54. (New) The method of claim 53, wherein steps (a), (b) and (c) 
comprise receiving a pre- compiled file containing the first and second 
criteria and first and second instructions. 

55. (New) The method of claim S3, wherein step (f) comprises comparing a 
first section of the first data packet to the first criterion to determine 
that the first data packet belongs to the first traffic flow, and step (g) 
comprises comparing a second section of the first data packet to the second 
criterion to determine the traffic flow class to which the first traffic flow 
belongs, the second section being non- exclusive of the first section. 

56. (Now) The method of claim 53, further comprising the step of 
receiving supplemental data pertaining to the first traffic flow, wherein the 
supplemental data is received outside of the first traffic flow and step (g) 
further comprises comparing the supplemental data to the second criterion to 
determine the class to which the first traffic flow belongs. 
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57. (New) The method of claim 55, wherein the supplemental data 
comprises data concerning network access rights of a user of the network, a 
traffic flow belonging to a user having a first level of network access rights 
being classified as belonging to the first traffic flow class, and a traffic 
flow belonging to a user having a second level of network access rights being 
classified as belonging to the second traffic flow class - 

5B. (New) The method of claim 57, wherein the first and second 
instructions specify respective first and second bandwidth allocations. 

5$. (New) The method of claim 56, wherein the supplemental data 
comprises data concerning network access requirements of a network device and 
the first traffic flow originates at the network device. 

60. (New) The method of claim 59, wherein the network access 
requirements of the network device are based on network access requirements of 
a client application executing on the network device, 

61. (New) The method of claim 56, wherein the supplemental data 
comprises data concerning network traffic conditions at a network device and 
the first traffic flow originates at the network device. 

62. (New) The method of claim 56, wherein the supplemental data is 
received from a registry within which data pertaining to multiple network 
devices is stored, 

63. (New) The method of claim 56, wherein the supplemental data 
identifies a work group to which a network device belongs and the firBt 
traffic flow originates at the network device. 

64. (New) The method of claim 56, wherein the supplemental data 
identifies a physical characteristic of a network device belongs and the first 
traffic flow originates at the network device. 

65. (New) The method of claim 56, wherein the supplemental data 
comprises data concerning network access requirements of a network device and 
the first traffic flow is being transmitted to the network device. 

66. (New) The method of claim, 65 wherein the network access 
requirements of the network device are based on network access requirements of 
a client application executing on the network device. 
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67. (New) The method of claim 56, wherein the supplemental data 
comprises data concerning network traffic conditions at a network device and 
the first traffic flow is being transmitted to the network device. 

69. (New) The method of claim, 56 wherein the supplemental data 
identifies a work group to which a network device belongs and the first 
traffic flow is being transmitted to the network device. 

69. (New) The method of claim 56, wherein the supplemental data 
identifies a physical characteristic of a network device belongs and the first 
traffic flow is being transmitted to the network device. 

70. (New) The method of claim 56, wherein the supplemental data pertains 
to a context of receipt of a second data packet belonging to the first traffic 
flow at a network device. 

71. (New) The method of claim 70 r wherein the supplemental data includes 
a time of day at which the second data packet was received at the network 
device . 

72. (New) The method of claim 53, wherein the first and second 
instructions pertain to any one of routing, switching or bridging the network 
traffic . 

73. INew) The method of claim 53, wherein the first traffic flow 
originated at a network device and the method further comprises the step of 
communicating information regarding the first data packet to the network 
device - 

74. (New) The method of claim 53, wherein at least one of the first and 
second criteria and the first and second instructions are provided by a 
network administrator. 

75. (New) The method of claim 53. wherein the network connection device 
has a first instruction set, the method further comprises, prior to step (a), 
instantiating a virtual machine on the network connection device, the virtual 
machine has a second instruction set. the second instruction set is a sub-set 
of the third instruction aet r and steps (a) through (h) are managed by the 
virtual machine. 
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76. (New) The method of claim 75, wherein Bteps (b) , (c) and (d) 
comprise receiving a pre -compiled file containing the first and second 
criteria and first and second instructions and the pre-compiled file is based 
on the second instruction set. 

77. (New) A method of operating a network connection device, the network 
connection device having a data ingress for receiving network traffic, a data 
egress for transmitting network traffic, and having at least a first 
criterion, a second criterion and first and second instructions stored 
therein, the first and second instructions being associated with respective 
first and second traffic flow classes, the network traffic being composed of 
at least first and second traffic flows, each traffic flow being composed of 
at least one data packet, and the method comprising: 

(a) receiving a first data packet that belongs to the first traffic 
flow at the ingress of the network connection device, 

(b) using the first criterion to determine that the first data packet 
belongs to the first traffic flow, 

(c) uBing the second criterion to determine a traffic flow class to 
which the first traffic flow belongs, 

(d) processing the first data packet according to the instructions 
associated with the flow class to which the first traffic flow belongs, and 

(d) transmitting the first data packet from the egress according to the 
instructions associated with the flow class to which the first traffic flow 
belongs . 

78. (New) The method of claim 77, further comprising, prior to step (a) 
the step of receiving a pre-compiled file containing the first and second 
criteria and first and second instructions* 

79. (New) The method of claim 77, wherein step (b) comprises comparing a 
first section of the first data packet to the first criterion to determine 
that the first data packet belongs to the first traffic flow, and step <c> 
comprises comparing a second section of the first data packet to the second 
criterion to determine the traffic flow class to which the first traffic flow 
belongs, the second section being non-exclusive of the first section. 

SO. (New) The method of claim 77, further comprising the step of 
receiving supplemental data pertaining to the first traffic flow, wherein the 
supplemental data is received outside of the first traffic flow and step {c> 
further comprises comparing the supplemental data to the second criterion to 
determine the class to which the first traffic flow belongs. 
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81. (New) The method of claim 80, wherein the supplemental data 
comprises data concerning network access rights of a user of the network, a 
traffic flow belonging to a user having a first level of network access rights 
being classified as belonging to the first traffic flow class, and a traffic 
flow belonging to a user having a second level of network access rights being 
classified as belonging to the second traffic flow class. 

82- (New) The method of claim 81, wherein the first and second 
instructions specify respective first and second bandwidth allocations. 

83. (New) The method of claim SO, wherein the supplemental data 
comprises data concerning network access requirements of a network device and 
the first traffic flow originates at the network device. 

84. (New) The method of claim 83 wherein the network access requirements 
of the network device are based on network access requirements of a client 
application executing on the network device. 

85. (New) The method of claim 80, wherein the supplemental data 
comprises data concerning network traffic conditions at a network device and 
the first traffic flow originates at the network device. 

85. (New) The method of claim 80/ wherein the supplemental data is 
received from a registry within which data pertaining to multiple network 
devices is stored. 

87. (New) The method of claim 80, wherein the supplemental data 
identifies a work group to which a network device belongs and the first 
traffic flow originates at the network device. 

88. (New) The method of claim 80, wherein the supplemental data 
identifies a physical characteristic of a network device belongs and the first 
traffic flow originates at the network device* 

89. (New) The method of claim 80 , wherein the supplemental data 
comprises data concerning network access requirements of a network device and 
the first traffic flow is being transmitted to the network device - 

90. (New) The method of claim 89, wherein the network access 
requirements of the network device are based on network access requirements of 
a client application executing on the network device. 
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91. (New) The method of claim 80, wherein the supplemental data 
comprises data concerning network traffic conditions at a network device and 
the first traffic flow is being transmitted to the network device. 

52. (New) The method of claim 80, wherein the supplemental data 
identifies a work group to which a network device belongs and the first 
traffic flow is being transmitted to the network device. 

93. (New) The method of claim 80, wherein the supplemental data 
identifies a physical characteristic of a network device belongs and the first 
traffic flow is being transmitted to the network device. 

94. (New) The method of claim 80, wherein the supplemental data pertains 
to a context of receipt of a second data packet belonging to the first traffic 
flow at a network device . 

95. (New) The method of claim 94, wherein the supplemental data includes 
a time of day at which the second data packet was received at the network 
device - 

96. (New) The method of claim 77, wherein the first and second 
instructions pertain to any one of routing, switching or bridging the network 
traffic . 

97. (New) The method of claim 77, wherein the first traffic flow 
originated at a network device and the method further comprises the step of 
communicating information regarding the first data packet to the network 
device. 

98. (New) The method of claim 77, wherein at least one of the first and 
second criteria and the first and second instructions are provided by a 
network administrator. 

99. (New) The method of claim 77, wherein the network connection device 
has a first instruction set, the method further comprises, prior to step (a), 
instantiating a virtual machine on the network connection device, the virtual 
machine has a second instruction set, the second instruction set is a sub-set 
of the third instruction set, and steps (a) through (d) are managed by the 
virtual machine. 
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100. (New) The method of claim 99, wherein the method comprises, prior 
to step (a) , receiving a pre-compiled file containing the first and second 
criteria and first and second instructions and the pre-compiled file is based 
on the second instruction set- 
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